kevmap

TechniquesT1098.005 › AN0103

AN0103 Analytic 0103

Identity Provider · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Adversary registers new devices to compromised user accounts to bypass MFA or conditional access policies via Azure Entra ID, Okta, or Duo self-enrollment portals.</p>
Detects
T1098.005 Device Registration
Part of
DET0036 Suspicious Device Registration via Entra ID or MFA Platform

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
azure:auditOperation IN ("Add device", "Add registered users to device", "Add registered owner to device")DC0010 User Account Modification
ApplicationLog:EntraIDPortalDeviceRegistration eventsDC0038 Application Log Content
azure:auditNew device object creationDC0087 Active Directory Object Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
ActorUserPrincipalNameDefine expected admin users to exclude known enrollment behavior
IP AddressScope internal vs. external device enrollment sources
TimeWindowAdjust for expected hours of legitimate self-enrollment